<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_phoenixcontactgmbhcokg</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:06:07 +0000</lastBuildDate>
    <item>
      <title>VDE-2017-001 — PHOENIX CONTACT: mGuard IKE daemon remote denial of service</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2017-001</link>
      <description>&lt;p&gt;Openswan 2.6.39 and earlier, which is used in the mGuard firmware version 8.0.0 to 8.5.1, allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Openswan 2.6.39 and earlier, which is used in the mGuard firmware version 8.0.0 to 8.5.1, allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2017-001</guid>
      <pubDate>Tue, 07 Mar 2017 11:05:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2017-002 — PHOENIX CONTACT: mGuard device manager (mdm) multiple vulnerabilities in Java SE</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2017-002</link>
      <description>&lt;p&gt;Multiple security issues and vulnerabilities in Oracle Java SE possibly affecting mGuard device manager (mdm / FL MGUARD DM) 1.8.0 and older.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple security issues and vulnerabilities in Oracle Java SE possibly affecting mGuard device manager (mdm / FL MGUARD DM) 1.8.0 and older.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2017-002</guid>
      <pubDate>Thu, 07 Sep 2017 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2017-003 — PHOENIX CONTACT: WLAN enabled devices utilising WPA2 encryption</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2017-003</link>
      <description>&lt;p&gt;Multiple security issues and vulnerabilities within the WPA2 standard have been identified and publicized by Mr. Mathy Vanhoef of KU Leuven. These vulnerabilities may allow the reinstallation of a pairwise transient key, a group key, or an integrity key on either a wireless client or a wireless access point (AP). In consequence, an attacker could establish a man-in-the-middle position between AP and client facilitating packet decryption and injection.&lt;/p&gt;
&lt;p&gt;Update A / Revision 2 - 2017-11-09
* Added a detailed list of affected products&lt;/p&gt;
&lt;p&gt;Update B / Revision 3 - 2018-09-24
* Added firmware update information, see section &amp;#34;Solution&amp;#34;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple security issues and vulnerabilities within the WPA2 standard have been identified and publicized by Mr. Mathy Vanhoef of KU Leuven. These vulnerabilities may allow the reinstallation of a pairwise transient key, a group key, or an integrity key on either a wireless client or a wireless access point (AP). In consequence, an attacker could establish a man-in-the-middle position between AP and client facilitating packet decryption and injection.&lt;/p&gt;
&lt;p&gt;Update A / Revision 2 - 2017-11-09
* Added a detailed list of affected products&lt;/p&gt;
&lt;p&gt;Update B / Revision 3 - 2018-09-24
* Added firmware update information, see section &amp;#34;Solution&amp;#34;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2017-003</guid>
      <pubDate>Thu, 09 Nov 2017 16:20:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2017-004 — PHOENIX CONTACT: FL COMSERVER cross-site scripting (XSS) vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2017-004</link>
      <description>&lt;p&gt;A cross-site scripting (XSS) vulnerability affects PHOENIX CONTACT FL COMSERVER products running firmware versions prior to 1.99, 2.20, or 2.40.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A cross-site scripting (XSS) vulnerability affects PHOENIX CONTACT FL COMSERVER products running firmware versions prior to 1.99, 2.20, or 2.40.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2017-004</guid>
      <pubDate>Tue, 05 Dec 2017 08:50:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2017-006 — PHOENIX CONTACT: FL SWITCH 3xxx/4xxx/48xx series web-service authentication bypass</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2017-006</link>
      <description>&lt;p&gt;PHOENIX CONTACT FL SWITCH 3xxx series, FL SWITCH 4xxx series, and FL SWITCH 48xx series products running firmware version 1.0 to 1.32 allow unauthenticated users with network access to gain administrative privileges (CVE-2017-16743) and expose information to unauthenticated users in Monitor Mode (CVE-2017-16741).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PHOENIX CONTACT FL SWITCH 3xxx series, FL SWITCH 4xxx series, and FL SWITCH 48xx series products running firmware version 1.0 to 1.32 allow unauthenticated users with network access to gain administrative privileges (CVE-2017-16743) and expose information to unauthenticated users in Monitor Mode (CVE-2017-16741).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2017-006</guid>
      <pubDate>Wed, 10 Jan 2018 09:36:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2018-001 — PHOENIX CONTACT: Advisory for mGuard products</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2018-001</link>
      <description>&lt;p&gt;The integrity of the mGuard firmware atomic update process cannot be guaranteed under all circumstances.&lt;/p&gt;
&lt;p&gt;The mGuard atomic update mechanism relies on internal checksums for the integrity verification of some portions of the update packages. The verification of these internal checksums may not always be performed correctly.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The integrity of the mGuard firmware atomic update process cannot be guaranteed under all circumstances.&lt;/p&gt;
&lt;p&gt;The mGuard atomic update mechanism relies on internal checksums for the integrity verification of some portions of the update packages. The verification of these internal checksums may not always be performed correctly.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2018-001</guid>
      <pubDate>Tue, 30 Jan 2018 09:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2018-003 — PHOENIX CONTACT: addressing Meltdown and Spectre vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2018-003</link>
      <description>&lt;p&gt;Several CPUs manufactured by Intel, AMD or based on ARM technology may leak information due to their internal operation if attacked by specifically written software executed on the affected systems.&lt;/p&gt;
&lt;p&gt;The information in this advisory is based on the statements of respective manufacturers.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several CPUs manufactured by Intel, AMD or based on ARM technology may leak information due to their internal operation if attacked by specifically written software executed on the affected systems.&lt;/p&gt;
&lt;p&gt;The information in this advisory is based on the statements of respective manufacturers.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2018-003</guid>
      <pubDate>Fri, 23 Mar 2018 09:43:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2018-004 — Phoenix Contact: FL SWITCH 3xxx/4xxx/48xx series through 1.33 allows Command Injection</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2018-004</link>
      <description>&lt;p&gt;An attacker with permission to transfer configuration files to/from the switch or permission to upgrade firmware, is able to execute arbitrary OS shell commands. CGI applications config_transfer.cgi and software_update.cgi are prone to OS command injection through targeted manipulation of their web-request headers.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker with permission to transfer configuration files to/from the switch or permission to upgrade firmware, is able to execute arbitrary OS shell commands. CGI applications config_transfer.cgi and software_update.cgi are prone to OS command injection through targeted manipulation of their web-request headers.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2018-004</guid>
      <pubDate>Wed, 16 May 2018 05:35:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2018-005 — Phoenix Contact: FL SWITCH 3xxx/4xxx/48xx series through 1.33 allows Information Exposure</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2018-005</link>
      <description>&lt;p&gt;Web interface CGI applications may copy the contents of the running configuration file to a commonly accessed file. Clever manipulation of a web login request can expose the contents of this file through to the web browser. A successful web interface login attempt is not required to read the configuration file contents.&lt;/p&gt;
&lt;p&gt;FL SWITCH Configuration File can be read by unauthenticated user.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Web interface CGI applications may copy the contents of the running configuration file to a commonly accessed file. Clever manipulation of a web login request can expose the contents of this file through to the web browser. A successful web interface login attempt is not required to read the configuration file contents.&lt;/p&gt;
&lt;p&gt;FL SWITCH Configuration File can be read by unauthenticated user.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2018-005</guid>
      <pubDate>Wed, 16 May 2018 05:35:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2018-006 — Phoenix Contact: FL SWITCH 3xxx/4xxx/48xx series through 1.33 has a Stack-based Buffer Overflow</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2018-006</link>
      <description>&lt;p&gt;An attacker may insert a carefully crafted cookie into a GET menu_pxc.cgi or GET index.cgi request to cause a buffer overflow that can initiate a Denial of Service attack and execute arbitrary code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker may insert a carefully crafted cookie into a GET menu_pxc.cgi or GET index.cgi request to cause a buffer overflow that can initiate a Denial of Service attack and execute arbitrary code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2018-006</guid>
      <pubDate>Wed, 16 May 2018 10:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
